# Development

Use the existing `.venv` and PostgreSQL `ccare_dev` database. Runtime dependencies
are pinned in requirements/base.txt; development and production extend it without
additional packages. Transitive dependencies are resolved by pip, not fully locked.

Keep `.env` local and populate DB_PASSWORD there. Never request passwords in chat
or include them in commands/logs. `.env.example` contains placeholders only.
Existing environment variables override dotenv values; `DB_PASSWORD` is read
from the process environment first and falls back to the local `.env` file when
it is absent, so a container or service manager can supply the credential on a
production host. Missing required values raise a named configuration error
without showing their values. The bootstrap never replaces an existing `.env`.
Production settings are documented in `PRODUCTION_DEPLOYMENT.md`.

The initial accounts migration creates the UUID User. AUTH_USER_MODEL must remain
accounts.User before any migrations. Do not fake migrations, recreate the existing
database, or change the user model after first migration without a migration plan.

Run from the project root with the virtual environment Python:

```powershell
python manage.py check
python manage.py makemigrations --check
python manage.py migrate
python manage.py showmigrations
python manage.py test
```

Django creates and destroys an isolated PostgreSQL test database. Ask your local
DBA to arrange test database privileges if creation is denied; this bootstrap does
not change PostgreSQL roles. The SimpleTestCase subset needs no database queries:
`python manage.py test tests.test_foundation.FoundationTests` (valid configuration
is still required). Full tests include persisted users and password hashing.

To verify the application database without printing credentials:

```powershell
python manage.py shell -c "from django.db import connection; from django.contrib.auth import get_user_model; connection.ensure_connection(); print('User table exists:', get_user_model()._meta.db_table in connection.introspection.table_names())"
```

Use createsuperuser interactively after migrations; no default admin credentials
are supplied. Keep uploaded media, collected static files, dumps, caches, and
secrets out of Git. No remote, commit, or push is part of this phase.
